package sys.cloud.escape.controller;

import org.springframework.web.bind.annotation.RequestMapping;
import org.springframework.web.bind.annotation.RequestMethod;
import org.springframework.web.bind.annotation.RestController;
import sys.cloud.escape.LeavelMessage;

/**
 * Created by shiyusen on 2017/3/23.
 */

@RestController
@RequestMapping("/escape")
public class EscapeController {

    @RequestMapping(value = "/say",method = RequestMethod.POST)
    public LeavelMessage say(){
        LeavelMessage leavelMessage=new LeavelMessage();
        leavelMessage.setContent("<script>alert()</script>");
        return leavelMessage;
    }
}
